UK Fraud Strategy Puts Banks On Notice: Prevention Is Becoming Core Obligation
By CU Today Staff —
LONDON—The U.K. government’s new fraud strategy is shifting more responsibility for stopping fraud onto banks and other infrastructure providers, signaling that reimbursing victims after the fact will no longer be enough, according to GlobalData.
The 2026-2029 strategy describes fraud as the U.K.’s largest crime type, with an estimated economic cost of at least £14.4 billion in 2023-24, and commits more than £250 million over three years to disrupting fraud, protecting consumers and strengthening enforcement.
GlobalData said the strategy points toward a broader compliance burden for banks, with regulators increasingly expecting fraud controls to be embedded throughout product design, customer onboarding, payment flows, authentication, account security, communications and money-mule detection. Banks already face customer due diligence, transaction monitoring and reimbursement requirements, but the new approach increasingly shifts the focus upstream toward preventing fraudulent transactions before losses occur.
The strategy acknowledges measures already adopted by the banking sector, including Confirmation of Payee, the Banking Protocol and mandatory reimbursement for eligible authorized push payment fraud, which returned £173 million to victims in its first year. Yet GlobalData noted fraud losses remain substantial, with at least £629.3 million stolen during the first half of 2025, including £371.8 million through unauthorized fraud.
More changes are coming. A Home Office call for evidence on APP fraud is expected in 2026, while the Financial Conduct Authority is set to examine good and poor practices in preventing APP fraud and the use of money mules. HM Treasury also plans to repeal existing Strong Customer Authentication technical standards, allowing the FCA to develop a more agile, outcomes-focused framework. GlobalData said that could mean banks are judged not simply on whether they followed prescribed controls, but on whether those controls adapted as fraud threats evolved.
GlobalData said banks should begin preparing by mapping fraud from initial customer contact through cash-out, strengthening identity and authentication controls, improving mule detection and payment warnings, and making greater use of behavioral signals. Banks also will need to document and test their controls and demonstrate effective board oversight. The result, GlobalData said, is a shift from reactive to proactive fraud compliance across the customer lifecycle—one likely to require significant investment as banks are increasingly viewed not only as victims of fraud, but as a critical last line of defense against it.
Originally reported by CU Today.